CVE-2011-4970
Last modified
CVE-2011-4970 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in LCG Disk Pool Manager (DPM) before 1.8.6, as used in EGI UDM, allow remote attackers to execute arbitrary SQL commands via the (1) r_token variable in the dpm_get_pending_req_by_token, (2) dpm_get_cpr_by_fullid, (3) dpm_get_cpr_by_surl, (4) dpm_get_cpr_by_surls, (5) dpm_get_gfr_by_fullid, (6) dpm_get_gfr_by_surl, (7) dpm_get_pfr_by_fullid, (8) dpm_get_pfr_by_surl, (9) dpm_get_req_by_token, (10) dpm_insert_cpr_entry, (11) dpm_insert_gfr_entry, (12) dpm_insert_pending_entry, (13) dpm_insert_pfr_entry, (14) dpm_insert_xferreq_entry, (15) dpm_list_cpr_entry, (16) dpm_list_gfr_entry, or (17) dpm_list_pfr_entry function; the (18) surl variable in the dpm_get_cpr_by_surl function; the (19) to_surl variable in the dpm_get_cpr_by_surls function; the (20) u_token variable in the dpm_get_pending_reqs_by_u_desc, (21) dpm_get_reqs_by_u_desc, (22) dpm_get_spcmd_by_u_desc, (23) dpm_insert_pending_entry, (24) dpm_insert_spcmd_entry, or (25) dpm_insert_xferreq_entry function; the (26) s_token variable in the dpm_get_spcmd_by_token, (27) dpm_insert_cpr_entry, (28) dpm_insert_gfr_entry, (29) dpm_insert_pfr_entry, (30) dpm_insert_spcmd_entry, (31) dpm_update_cpr_entry, (32) dpm_update_gfr_entry, or (33) dpm_update_pfr_entry function; or remote administrators to execute arbitrary SQL commands via the (34) poolname variable in the dpm_get_pool_entry, (35) dpm_insert_fs_entry, (36) dpm_insert_pool_entry, (37) dpm_insert_spcmd_entry, (38) dpm_list_fs_entry, or (39) dpm_update_spcmd_entry function.. EPSS estimates a 1.54% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in LCG Disk Pool Manager (DPM) before 1.8.6, as used in EGI UDM, allow remote attackers to execute arbitrary SQL commands via the (1) r_token variable in the dpm_get_pending_req_by_token, (2) dpm_get_cpr_by_fullid, (3) dpm_get_cpr_by_surl, (4) dpm_get_cpr_by_surls, (5) dpm_get_gfr_by_fullid, (6) dpm_get_gfr_by_surl, (7) dpm_get_pfr_by_fullid, (8) dpm_get_pfr_by_surl, (9) dpm_get_req_by_token, (10) dpm_insert_cpr_entry, (11) dpm_insert_gfr_entry, (12) dpm_insert_pending_entry, (13) dpm_insert_pfr_entry, (14) dpm_insert_xferreq_entry, (15) dpm_list_cpr_entry, (16) dpm_list_gfr_entry, or (17) dpm_list_pfr_entry function; the (18) surl variable in the dpm_get_cpr_by_surl function; the (19) to_surl variable in the dpm_get_cpr_by_surls function; the (20) u_token variable in the dpm_get_pending_reqs_by_u_desc, (21) dpm_get_reqs_by_u_desc, (22) dpm_get_spcmd_by_u_desc, (23) dpm_insert_pending_entry, (24) dpm_insert_spcmd_entry, or (25) dpm_insert_xferreq_entry function; the (26) s_token variable in the dpm_get_spcmd_by_token, (27) dpm_insert_cpr_entry, (28) dpm_insert_gfr_entry, (29) dpm_insert_pfr_entry, (30) dpm_insert_spcmd_entry, (31) dpm_update_cpr_entry, (32) dpm_update_gfr_entry, or (33) dpm_update_pfr_entry function; or remote administrators to execute arbitrary SQL commands via the (34) poolname variable in the dpm_get_pool_entry, (35) dpm_insert_fs_entry, (36) dpm_insert_pool_entry, (37) dpm_insert_spcmd_entry, (38) dpm_list_fs_entry, or (39) dpm_update_spcmd_entry function.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Disk Pool Manager Project | Disk Pool Manager | <= 1.8.1 |
| Disk Pool Manager Project | Disk Pool Manager | 1.8.2 |
| Disk Pool Manager Project | Disk Pool Manager | 1.8.3 |
| Disk Pool Manager Project | Disk Pool Manager | 1.8.5 |
References
- http://secunia.com/advisories/52487Vendor Advisory
- https://wiki.egi.eu/wiki/SVG:Advisory-SVG-2012-2683Patch, Vendor Advisory
- http://secunia.com/advisories/52487Vendor Advisory
- https://wiki.egi.eu/wiki/SVG:Advisory-SVG-2012-2683Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-4970?
How severe is CVE-2011-4970?
How do I fix CVE-2011-4970?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-4964Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2011-4965Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2011-4966modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when…
- CVE-2011-4967tog-Pegasus has a package hash collision DoS vulnerability7.5
- CVE-2011-4968nginx http proxy module does not verify peer identity of htt…4.8
- CVE-2011-4969Cross-site scripting (XSS) vulnerability in jQuery before 1.…
- CVE-2011-4971Multiple integer signedness errors in the (1) process_bin_sa…
- CVE-2011-4972hook_file_download in the CKEditor module 7.x-1.4 for Drupal…7.5
- CVE-2011-4973Authentication bypass vulnerability in mod_nss 1.0.8 allows …
- CVE-2011-4974Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2011-4975Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2011-4976Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2011-4970?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
